CVE-2025-63650: High severity monkey vulnerability
Published Jan 29, 2026
·Updated
An out-of-bounds read in the mkptrtobuf in mkcore function (mkmemory.c) of monkey commit f37e984 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request to the server.
Affected Software
2 affected components
monkey
Monkey-project Monkey<=1.8.5
Event History
Jan 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63650?
CVE-2025-63650 has a high severity level due to its potential to cause Denial of Service (DoS) attacks.
2
How do I fix CVE-2025-63650?
To fix CVE-2025-63650, update to the latest version of Monkey that addresses this vulnerability.
3
What causes CVE-2025-63650?
CVE-2025-63650 is caused by an out-of-bounds read in the mk_ptr_to_buf function of mk_memory.c in the Monkey project.
4
Who is affected by CVE-2025-63650?
Users of Monkey versions up to and including 1.8.5 are affected by CVE-2025-63650.
5
What types of attacks can be launched using CVE-2025-63650?
CV-2025-63650 can be exploited by attackers to launch Denial of Service (DoS) attacks via crafted HTTP requests.